Hi,

we have an application that is HTTP based hosted on a Windows 2003 Server
(SP1) with IIS 6.0 which has been working fine to date. Authentication to
the websites has been using Windows Integrated security and basic
authentication.

All of a sudden we are now having a serious problem in that it appears that
the server is only allowing HTTP requests to the server where the user
making the request is an administrator on the box. The websites that are
hosted on this server can be accessed when connected as a local admin user
but are rejected with a "HTTP 500 - Internal Internet Server Error" for non
administrative users. When I take the friendly HTTP messages option off the
error is "Unable to contact local security authority".

It appears to me that the server has been changed in some shape or form and
that security has been tightened in some way but I can't find where. We have
additional servers in this environment some of which are also displaying
this behaviour and some of which aren't (the only difference being that the
server that isn't has not been patched recently).

Has anybody out there come across a similar problem ? If so I'd be really
appreciative if you could give me any help on tracking down what is causing
this as it causing us major problems. Are there patches that could be
causing this or could it be another tool causing this (IIS Lockdown, URLScan
etc.).

Any information greatly appreciated.

Derek